全局管理员如何通过MS Graph API批量访问所有用户OneDrive for Business文件
全局管理员通过Microsoft Graph API批量访问所有用户OneDrive for Business文件的方法
核心原因
手动创建文件链接的本质是为管理员授予了目标用户OneDrive站点的访问权限,要实现批量操作,只需程序化完成这一权限授予步骤即可。
前提条件确认
- 确保Azure AD注册应用已配置应用权限(非委派权限)
Files.ReadWrite.All、Sites.ReadWrite.All、User.Read.All,且已完成全局管理员同意。 - 操作账号需具备全局管理员权限,或拥有足够的目录权限以管理用户OneDrive站点权限。
程序化实现方案
方案一:使用Microsoft Graph PowerShell模块
- 安装并连接Graph PowerShell环境:
Install-Module Microsoft.Graph -Force Connect-MgGraph -Scopes "Directory.Read.All", "Sites.FullControl.All" - 获取目标用户列表(可按需过滤,比如排除禁用用户):
$users = Get-MgUser -All $true -Select Id, UserPrincipalName -Filter "accountEnabled eq true" - 批量授予管理员OneDrive访问权限:
# 替换为你的全局管理员用户ID $adminUserId = "<你的管理员用户ID>" foreach ($user in $users) { try { # 获取用户OneDrive站点信息 $drive = Get-MgUserDrive -UserId $user.Id # 授予管理员完全控制权限 New-MgSitePermission -SiteId $drive.Id -Roles @("fullControl") -GrantedToIdentities @(@{ User = @{ Id = $adminUserId } }) Write-Host "已授予对用户 $($user.UserPrincipalName) OneDrive的访问权限" } catch { Write-Host "处理用户 $($user.UserPrincipalName) 时出错: $_" } }
方案二:直接调用Microsoft Graph API
- 获取所有目标用户ID:
GET https://graph.microsoft.com/v1.0/users?$select=id,userPrincipalName&$filter=accountEnabled eq true - 对每个用户,先获取其OneDrive站点ID:
GET https://graph.microsoft.com/v1.0/users/{user-id}/drive - 发送POST请求授予管理员权限:
POST https://graph.microsoft.com/v1.0/sites/{site-id}/permissions Content-Type: application/json { "roles": ["fullControl"], "grantedToIdentities": [ { "user": { "id": "<管理员用户ID>" } } ] }
验证权限
完成批量授权后,即可直接调用以下接口访问任意用户的OneDrive文件:
GET https://graph.microsoft.com/v1.0/users/{user-id}/drive/root/children
内容的提问来源于stack exchange,提问作者Gags
相关产品推荐
相关产品推荐

